Summary
The remote host is missing an update to gforge
announced via advisory DSA 1945-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201945-1
Insight
Sylvain Beucler discovered that gforge, a collaborative development tool, is prone to a symlink attack, which allows local users to perform a denial of service attack by overwriting arbitrary files.
For the stable distribution (lenny), this problem has been fixed in version 4.7~rc2-7lenny3.
The oldstable distribution (etch), this problem has been fixed in version 4.5.14-22etch13.
For the testing distribution (squeeze), this problem will be fixed soon.
For the unstable distribution (sid), this problem has been fixed in version 4.8.2-1.
We recommend that you upgrade your gforge packages.
Severity
Classification
-
CVE CVE-2009-3304 -
CVSS Base Score: 3.3
AV:L/AC:M/Au:N/C:N/I:P/A:P
Related Vulnerabilities